home.social

#impersonation — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #impersonation, aggregated by home.social.

  1. Latest strange “AI” (LLM) behavior in the #indieweb community: the same entity that showed up a few days ago (for a second time) joined the IndieWeb Slack (a bridge to our IRC) yesterday, introduced itself again, and seemingly engaged in human-like chat behavior.

    https://chat.indieweb.org/2026-08-20#t1787211025380600

    Very uncanny valley.

    The content of its chats was fascinating in that it was polite, seemingly responsive to what people said in response to it, and gave the appearance of understanding, though it’s impossible to tell if it was acting fully autonomously or semi-autonomously in front of a human puppeteer.

    Its choice of syntax was also interesting, mimicking informality with all lowercase text (except for its admission of being an “AI”), including lowercase "i" instead of "I", though with proper punctuation, periods, commas, 7-bit apostrophes, and a couple of Unicode em-dashes.

    Even stranger than its content or syntax were the time delays in its replies.

    Typical (pre-LLM) chatbots are (nearly) instantly responsive, and we use a few in the IndieWeb chats (e.g. Loqi, iwc-archive-bot).

    This LLM bot seemed to "wait" several minutes, from 6 to apparently 33 minutes, before responding to replies directed at it. Unclear if this was a tactic to appear/seem more “human” or if it was literally taking that much time processing, or perhaps a mix of processing time and human puppeteer manual “approval” of its replies before it posted.

    It departed on its own and we have banned that particular Slack account, however the same thing could happen again with another LLM bot.

    There is an active discussion in both the IndieWeb chat channels and iterations/comments on a proposed AI policy:

    https://indieweb.org/AI_policy#Brainstorming_HWC_policy

    If you have thoughts for how (if at all) LLM chatbots should use (or not) and/or interact with community chat channels or other resources, let us know what you think.

    https://chat.indieweb.org/meta

    Previously, previously:
    * https://tantek.com/2026/231/t1/more-weirdness-ai-chat-llm-bot
    * https://tantek.com/2026/217/t1/indieweb-ai-policy

    This is post 16 of #100PostsOfIndieWeb. #100Posts #indieweb
    #AI #AIs #LLM #LLMs #pretending #impersonating #impersonation #uncannyValley #Slack #chat #IRC #AIpolicy #chatbot #chatbots
    #Blaugust #Blaugust2026

    https://tantek.com/2026/231/t1/more-weirdness-ai-chat-llm-bot
    https://tantek.com/2026/238/t1/indieweb-your-own-words-actions

  2. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  3. Duolingo Goes “AI-First” – DTNSB 5008

    US Congress passed the bipartisan Take It Down Act, and Bodie Grimm shares two EV models that you need to know about.

    Starring Jason Howell, Shannon Morse, and Bodie Grimm.

    MP3 Download

    Follow us on Bluesky, Mastodon, X Instgram, Threads, YouTube and Twitch

    Please SUBSCRIBE HERE for free or get DTNS ad-free.

    A special thanks to all our supporters–without you, none of this would be possible.

    If you enjoy what you see you can support the show on Patreon, Thank you!

    Become a Patron!

    Send to email to [email protected]

    Show Notes

    #adapters #affiliateLinks #AI #AIExperiment #AIFirst #Amazon #Android #automotiveTrends #bipartisan #BodieGrimm #broadband #carPrices #chargeOnlyCable #ChatGPT #consumerElectronics #contractors #dataEthics #deepfakes #DenmarkStudy #Duolingo #eCommerce #economicImpact #economists #electricVehicles #endOfService #ethics #Europe #EVs #generativeAI #GoogleCompetitor #impersonation #internetAccess #jobAutomation #JuiceJacking #KilowattPodcast #Kuiper #legalAction #legislation #LG #LGBridge #lowEarthOrbit #nonconsensualContent #NorthAmerica #OnePlus #onlineSafety #OpenAI #OTAUpdates #phoneSupport #priceDrop #privacy #productRecommendations #productivity #rChangemyview #Reddit #refunds #revengePorn #ruralAreas #satelliteInternet #security #shopping #smartphones #smartwatch #softwareUpdates #Starlink #TakeItDownAct #tariffs #travelSafety #UniversityOfZurich #USCongress #USPricing #USBCondom #USBC #Watch3 #workplaceAutomation